Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


Configuration Problems with a Cisco Site-to-Site VPN

Posted on 2009-04-04
Medium Priority
Last Modified: 2012-05-06
I'm trying to add a site-to-site VPN connection to a Cisco 1711 that already has a working EZvpn setup.  I have been over this to the point that I'm just not seeing what I'm missing.  It is failing to establish IKE.  Any pointers as to what I'm missing would be most appreciated.  This is the Hub router config.
Question by:NelsonS74
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment

Accepted Solution

Donboo earned 2000 total points
ID: 24067915
You named you static map "dynmap" and gave the reference to your dynamic-map (which you also called dynmap) as first priority whatever static you enter after here dosnt matter as they will match your dynamic map and as the site-to-site dosnt have any groupname to match a ISAKMP will not be established.

crypto map dynmap (Static map name) 1 ipsec-isakmp dynamic dynmap (dynamic map name)

So change your dynamic map to a higher prio like 65000 and add you static as a lower number. that should get you to first base :P

Example of static map with dynamic map:
crypto dynamic-map DYN-VPN 1
 set transform-set groupname1
 set isakmp-profile groupname1-profile
crypto dynamic-map DYN-VPN 2
 set transform-set groupname2
 set isakmp-profile groupname2-profile
crypto map VPN 1 ipsec-isakmp
 set peer x.x.x.x
 set transform-set CUST1-L2L
 set pfs group2
 set isakmp-profile CUST1-L2L
 match address CUST1-L2L
crypto map VPN 2 ipsec-isakmp
 set peer y.y.y.y
 set transform-set CUST2-L2L
 set pfs group2
 set isakmp-profile CUST2-L2L
 match address CUST2-L2L
crypto map VPN 65000 ipsec-isakmp dynamic DYN-VPN

Featured Post

Ask an Anonymous Question!

Don't feel intimidated by what you don't know. Ask your question anonymously. It's easy! Learn more and upgrade.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question